CVE-2020-26867
🟠 Łataj w tym tygodniu
Deserializacja niezaufanych danych w ARC Informatique PcVue umożliwia zdalne wykonanie kodu.
CVSS
9.8
EPSS
3.7%
Exploit
none
Vendor
arcinfo
Opis źródłowy (NVD)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
deserialization
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.7% |
| Opublikowano (NVD) | 2020-10-12 14:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 18:32:08 UTC |
Referencje
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2020/10/09/klcert-20-015-remote-code-execution-in-arc-informatique-pcvue/ (vulnerability@kaspersky.com) [Broken Link]
- https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03 (vulnerability@kaspersky.com) [Third Party Advisory, US Government Resource]
- https://www.pcvuesolutions.com/security (vulnerability@kaspersky.com) [Vendor Advisory]
- https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1076-security-bulletin-2020-1 (vulnerability@kaspersky.com) [Permissions Required, Vendor Advisory]